Impact
The vulnerability resides in the UEFI BIOS embedded shell of Insyde Software’s InsydeH2O firmware. It allows an attacker to execute shell commands or startup scripts that can override the secure boot validation process. This bypass permits the booting of unauthorized firmware or malware, effectively compromising the authenticity of the firmware and the integrity of the system’s boot chain. The weakness is classified as CWE-489, implying that code or command generation is improperly controlled.
Affected Systems
System owners of InsydeH2O firmware that have not applied the recent firmware updates are affected. The vendor’s official fix is available for Kernel 5.3 in firmware 05.3A.25, Kernel 5.4 in firmware 05.48.25, Kernel 5.5 in firmware 05.56.25, and Kernel 5.6 in firmware 05.63.25. Any prior firmware reflecting earlier kernel versions remains vulnerable.
Risk and Exploitability
The CVSS score of 8.2 reflects the high severity of this issue. EPSS data is not currently available, so the exact likelihood of exploitation cannot be quantified, but the lack of a KEV listing does not diminish the urgency. The likely attack vector appears to require local interaction with the UEFI environment, such as physical access or control over the boot configuration. Once the embedded shell is abused, an attacker can persistently install malicious code at the firmware level, undermining all subsequent security controls.
OpenCVE Enrichment